Advisories for Maven/Org.springframework/Spring-Websocket package

2017

Improper Input Validation

Under some situations, the Spring Framework is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.

2015